---
title: "Use Case 4: Quarantining Endpoints Generating SOC Insights"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDIntegrationCiscoISE/1544716795/Use%20Case%204%3A%20Quarantining%20Endpoints%20Generating%20SOC%20Insights"
format: markdown
---
Endpoints that generate DNS activity resulting in SOC Insights are automatically quarantined upon insight creation.

Initiate DNS queries from the client machine that are likely to trigger SOC Insight generation; once the insight is created, all associated assets are automatically added to the quarantine list in Cisco ISE.

![image-20250620-052631.png](media://066ec701-1906-4269-8683-47d10d907a20)

![image](media://fcd0a64c-0641-4265-807b-af54fd10c99c)

![image](media://921fd98c-b7c4-46e1-b08c-e3faeff49010)

![image](media://fb70fe36-e69a-4f06-a298-ca02440399a3)